Featured Article

Should we ban ransom payments?

Starving hackers of their profits isn’t so simple

Comment

an illustration of patterned 100 dollar bills on a green background
Image Credits: zf L / Getty Images

As cybercriminals continue to reap the financial rewards of their attacks, talk of a federal ban on ransom payments is getting louder.

U.S. officials have long urged against paying ransom demands. But while several U.S. states — including North Carolina and Florida — have made it illegal for local government entities to pay ransom demands, the Biden administration as recently as last fall decided against an outright national ban on ransom payments.

It’s easy to see why. Not only would banning ransom payment be difficult to enforce and require complex mechanisms not yet in place, but critics argue that criminalizing payments to hackers ultimately punishes the victims of cybercrime who could ultimately face legal repercussions for doing what they deem necessary to protect — or, in some cases, save — their business.

Although challenges persist, it appears the U.S. government’s mindset might be starting to shift.

In October 2023, a U.S.-led alliance of more than 40 countries vowed as governments not to pay ransoms to cybercriminals in a bid to starve the hackers from their source of income.

Since then, just as talk of a potential ransom payment ban has gotten louder, so has the ransomware activity.

In 2024 alone, we’ve seen financially driven hackers brazenly mass-exploiting flaws in various remote access tools to deploy ransomware; notorious ransomware groups bounce back from government takedowns; and disruption at healthcare providers across the U.S. after a ransomware attack on prescription processing giant Change Healthcare.

Is a ban on ransom payments the solution? It’s not that simple.

To ban or not to ban?

On the face of it, a ransom payment ban makes logical sense. If victim organizations are prohibited from paying, attackers will have less of a financial incentive to steal their data. In theory, this means those seeking to get rich quick will be forced to go elsewhere — and that ransomware attacks could become a thing of the past.

The other side is that many believe making ransom payments illegal is an over-simplistic solution to a complex problem.

Ransomware is a global problem. For a ban on ransom payments to be successful, international and universal regulation would need to be implemented — which, given varying international standards around ransom payments, would be almost impossible to enforce. It would also require governments that grant safe harbor to cybercriminals — Russia gets an obvious namecheck — to crack down within their own borders, which they’re not incentivized to do.

A blanket ban on ransom payments would also likely necessitate exceptions in dire circumstances, such as ransomware attacks involving the risk of loss of life in medical facilities or threats to national critical infrastructure.

These exceptions, while logical, would also apply to the hackers behind these attacks, which could lead to an assault on the nation’s critical infrastructure. And as long as cybercriminals continue to make money, ransomware and extortion threats won’t go away.

Some also argue that if a ransom payment ban were imposed in the U.S. or any other highly victimized country, companies would likely stop reporting these incidents to the authorities, effectively reversing all of the past cooperation between victims and law enforcement.

Allan Liska, a ransomware expert and threat intelligence analyst at Recorded Future, told TechCrunch that before a blanket ban on payments to ransomware groups — or a ban with some exceptions — is enforced, we need to make a concerted effort to better catalog the number of ransomware attacks “so we can make an informed decision on the best steps.”

“In the United States, we actually have two test cases that prove this point,” said Liska. “Both North Carolina and Florida have implemented bans on public entities paying ransom to ransomware groups. In both cases, looking at the data from a year before the laws went into effect and the year after, there has been no discernible change in the number of publicly reported ransomware attacks against public organizations in those States.”

Would a ban even work?

There’s also the issue of how effective a ransom payment ban would be.

As history has shown, hackers have little regard for rules. Even when an organization does relent to an attacker’s ransom demand, the victim’s data is not always deleted — as demonstrated by the recent lawful takedown of the LockBit ransomware gang.

Given the brazen nature of these attackers, it’s unlikely that they would be deterred by a ban on ransom payments. Rather, criminalizing payment would likely push it further underground and would likely encourage attackers to change tactics, becoming more covert in their operations and transactions.

“Are ransom payments bad? Yes, there is no net good to society that comes from paying ransomware groups, in fact, there is a direct net harm to society by paying these threat actors,” said Liska.

“Will banning ransom payments stop ransomware groups from carrying out attacks? The answer to that is unequivocally no.”

Read more on TechCrunch:

Why are ransomware gangs making so much money?

More TechCrunch

The U.K.’s self-proclaimed “world-leading” regulations for self-driving cars are now official, after the Automated Vehicles (AV) Act received royal assent — the final rubber stamp any legislation must go through…

UK’s autonomous vehicle legislation becomes law, paving the way for first driverless cars by 2026

ChatGPT, OpenAI’s text-generating AI chatbot, has taken the world by storm. What started as a tool to hyper-charge productivity through writing essays and code with short text prompts has evolved…

ChatGPT: Everything you need to know about the AI-powered chatbot

SoLo Funds CEO Travis Holoway: “Regulators seem driven by press releases when they should be motivated by true consumer protection and empowering equitable solutions.”

Fintech lender Solo Funds is being sued again by the government over its lending practices

Hard tech startups generate a lot of buzz, but there’s a growing cohort of companies building digital tools squarely focused on making hard tech development faster, more efficient, and —…

Rollup wants to be the hardware engineer’s workhorse

TechCrunch Disrupt 2024 is not just about groundbreaking innovations, insightful panels, and visionary speakers — it’s also about listening to YOU, the audience, and what you feel is top of…

Disrupt Audience Choice vote closes Friday

Google says the new SDK would help Google expand on its core mission of connecting the right audience to the right content at the right time.

Google is launching a new Android feature to drive users back into their installed apps

Jolla has taken the official wraps off the first version of its personal server-based AI assistant in the making. The reborn startup is building a privacy-focused AI device — aka…

Jolla debuts privacy-focused AI hardware

OpenAI is removing one of the voices used by ChatGPT after users found that it sounded similar to Scarlett Johansson, the company announced on Monday. The voice, called Sky, is…

OpenAI to remove ChatGPT’s Scarlett Johansson-like voice

The ChatGPT mobile app’s net revenue first jumped 22% on the day of the GPT-4o launch and continued to grow in the following days.

ChatGPT’s mobile app revenue saw its biggest spike yet following GPT-4o launch

Dating app maker Bumble has acquired Geneva, an online platform built around forming real-world groups and clubs. The company said that the deal is designed to help it expand its…

Bumble buys community building app Geneva to expand further into friendships

CyberArk — one of the army of larger security companies founded out of Israel — is acquiring Venafi, a specialist in machine identity, for $1.54 billion. 

CyberArk snaps up Venafi for $1.54B to ramp up in machine-to-machine security

Founder-market fit is one of the most crucial factors in a startup’s success, and operators (someone involved in the day-to-day operations of a startup) turned founders have an almost unfair advantage…

OpenseedVC, which backs operators in Africa and Europe starting their companies, reaches first close of $10M fund

A Singapore High Court has effectively approved Pine Labs’ request to shift its operations to India.

Pine Labs gets Singapore court approval to shift base to India

The AI Safety Institute, a U.K. body that aims to assess and address risks in AI platforms, has said it will open a second location in San Francisco. 

UK opens office in San Francisco to tackle AI risk

Companies are always looking for an edge, and searching for ways to encourage their employees to innovate. One way to do that is by running an internal hackathon around a…

Why companies are turning to internal hackathons

Featured Article

I’m rooting for Melinda French Gates to fix tech’s broken ‘brilliant jerk’ culture

Women in tech still face a shocking level of mistreatment at work. Melinda French Gates is one of the few working to change that.

1 day ago
I’m rooting for Melinda French Gates to fix tech’s  broken ‘brilliant jerk’ culture

Blue Origin has successfully completed its NS-25 mission, resuming crewed flights for the first time in nearly two years. The mission brought six tourist crew members to the edge of…

Blue Origin successfully launches its first crewed mission since 2022

Creative Artists Agency (CAA), one of the top entertainment and sports talent agencies, is hoping to be at the forefront of AI protection services for celebrities in Hollywood. With many…

Hollywood agency CAA aims to help stars manage their own AI likenesses

Expedia says Rathi Murthy and Sreenivas Rachamadugu, respectively its CTO and senior vice president of core services product & engineering, are no longer employed at the travel booking company. In…

Expedia says two execs dismissed after ‘violation of company policy’

Welcome back to TechCrunch’s Week in Review. This week had two major events from OpenAI and Google. OpenAI’s spring update event saw the reveal of its new model, GPT-4o, which…

OpenAI and Google lay out their competing AI visions

When Jeffrey Wang posted to X asking if anyone wanted to go in on an order of fancy-but-affordable office nap pods, he didn’t expect the post to go viral.

With AI startups booming, nap pods and Silicon Valley hustle culture are back

OpenAI’s Superalignment team, responsible for developing ways to govern and steer “superintelligent” AI systems, was promised 20% of the company’s compute resources, according to a person from that team. But…

OpenAI created a team to control ‘superintelligent’ AI — then let it wither, source says

A new crop of early-stage startups — along with some recent VC investments — illustrates a niche emerging in the autonomous vehicle technology sector. Unlike the companies bringing robotaxis to…

VCs and the military are fueling self-driving startups that don’t need roads

When the founders of Sagetap, Sahil Khanna and Kevin Hughes, started working at early-stage enterprise software startups, they were surprised to find that the companies they worked at were trying…

Deal Dive: Sagetap looks to bring enterprise software sales into the 21st century

Keeping up with an industry as fast-moving as AI is a tall order. So until an AI can do it for you, here’s a handy roundup of recent stories in the world…

This Week in AI: OpenAI moves away from safety

After Apple loosened its App Store guidelines to permit game emulators, the retro game emulator Delta — an app 10 years in the making — hit the top of the…

Adobe comes after indie game emulator Delta for copying its logo

Meta is once again taking on its competitors by developing a feature that borrows concepts from others — in this case, BeReal and Snapchat. The company is developing a feature…

Meta’s latest experiment borrows from BeReal’s and Snapchat’s core ideas

Welcome to Startups Weekly! We’ve been drowning in AI news this week, with Google’s I/O setting the pace. And Elon Musk rages against the machine.

Startups Weekly: It’s the dawning of the age of AI — plus,  Musk is raging against the machine

IndieBio’s Bay Area incubator is about to debut its 15th cohort of biotech startups. We took special note of a few, which were making some major, bordering on ludicrous, claims…

IndieBio’s SF incubator lineup is making some wild biotech promises

YouTube TV has announced that its multiview feature for watching four streams at once is now available on Android phones and tablets. The Android launch comes two months after YouTube…

YouTube TV’s ‘multiview’ feature is now available on Android phones and tablets